08 Data Management Flashcards
What is the Data Protection Act 2018?
It’s the UK’s implementation of the General Data Protection Regulation 2016 (GDPR)
It controls how your personal information is used by organisations, businesses or the government.
What is GDPR?
- General data protection regulation
- Relates to personal data
- Aims to create a single data protection regime for anyone doing business in the EU and to empower individuals to take control of how their data is used by third parties
- Gives people stronger rights to be informed about how their personal information is used
When did GDPR come into force?
25th May 2018
What are the key requirements under GDPR?
- Obligation to conduction data protection impact assessments for high risk holding of data
- New rights for individuals to have access to information on what personal data is held and to have it erased
- A data controller decides how and why personal data is processed and is directly responsible for GDPR
- ‘Data accountability’ ensuring that organisations can prove to the Information Commissioners Office (ICO) how they comply with the new regulations
What happens if you breach GDPR? What is the penalty?
- Data security breaches need to be reported to Information Commissioners Office (ICO) within 72 hours where there is a loss of personal data and a risk of harm to individuals
- An increase in fines up to 4% global turnover of the company or €20m (whichever is the greater)
- Policed by the ICO
Non-disclosure agreement
A non-disclosure agreement is a legally binding contract that establishes a confidential relationship. The party or parties signing the agreement agree that sensitive information they may obtain will not be made available to any others.
Difference between data and information
Data is raw facts/unauthorised facts/simple and seemingly random/useless until its organised Raw Facts(preliminary data) Example: tender boq data we need to collect and organize all data for final decision making; Information is when data is processed/organised/structure/presented as to make it useful
What does it mean by EDMS?
Electronic Document Management Systems
What are the Legal aspect of EDMS?
Copyright
Data Protection Act 1988 UK (new data protection act is 2018)
Gives individual the right to know what information is held about them;
Ensures that personal information is handled properly
Anyone who processes personal information must comply with 8 principles, which
• Fairly and lawfully protect
• Processed for limited purposes
• Adequate, relevant and not excess
• Accurate and up to date
• Not kept for longer than is necessary
• Processed in line with your rights
• Secured